{"schema_version":"1.7.5","id":"CVE-2026-53021","published":"2026-06-24T16:29:30.671Z","modified":"2026-07-28T18:30:26.117097390Z","related":["SUSE-SU-2026:22742-1","SUSE-SU-2026:22769-1","SUSE-SU-2026:22809-1","SUSE-SU-2026:22810-1","SUSE-SU-2026:22812-1","SUSE-SU-2026:22835-1","SUSE-SU-2026:22903-1","SUSE-SU-2026:22904-1","SUSE-SU-2026:3130-1","SUSE-SU-2026:3166-1","openSUSE-SU-2026:21388-1"],"summary":"scsi: target: core: Fix integer overflow in UNMAP bounds check","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: core: Fix integer overflow in UNMAP bounds check\n\nsbc_execute_unmap() checks LBA + range does not exceed the device capacity,\nbut does not guard against LBA + range wrapping around on 64-bit overflow.\n\nAdd an overflow check matching the pattern already used for WRITE_SAME in\nthe same file.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"86d7182985d25900929adce14fffd729cc8c6fb8"},{"fixed":"c08ab702c4699c6efb9d60bdb15b73e7a627ee7e"},{"fixed":"2e1ed9a7b6ea5bfefb5d80a02b1c71c7dee1f0dd"},{"fixed":"5efc3ef4758f8d98c257419fa21daca3227de61a"},{"fixed":"d7aef29573c7c5cdb2dfad939253287a6329c2a4"},{"fixed":"3facdecc3fcf115cc4f9b3d8f118d6705e2456a8"},{"fixed":"51075df70c46e60a9773f2dcd28299e40dac36fb"},{"fixed":"02115986d027ade793e7f6be87e91d6a796d0aa3"},{"fixed":"2bf2d65f76697820dbc4227d13866293576dd90a"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53021.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.10.0"},{"fixed":"5.10.258"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.209"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.175"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.141"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.91"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.33"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.10"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53021.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/02115986d027ade793e7f6be87e91d6a796d0aa3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2bf2d65f76697820dbc4227d13866293576dd90a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2e1ed9a7b6ea5bfefb5d80a02b1c71c7dee1f0dd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3facdecc3fcf115cc4f9b3d8f118d6705e2456a8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/51075df70c46e60a9773f2dcd28299e40dac36fb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5efc3ef4758f8d98c257419fa21daca3227de61a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c08ab702c4699c6efb9d60bdb15b73e7a627ee7e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d7aef29573c7c5cdb2dfad939253287a6329c2a4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53021.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53021"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53021.json"}}